Knowledge

7 entries

practitioner au-compliance hardening frameworks

Essential Eight evidence

How to show you actually did the Essential Eight. Scope, artefact, date, owner. Overall maturity is the weakest strategy, not the average.

practitioner au-compliance frameworks cloud

IRAP

Infosec Registered Assessors Program. ASD-endorsed assessors test systems and cloud against the ISM. The report is evidence. Authorisation stays with you.

practitioner au-compliance IR

NDB clock

The Notifiable Data Breaches assessment and notify clocks. OAIC, not a breach tray. Thirty days to assess a suspicion; notify as soon as practicable once it is eligible.

practitioner au-compliance frameworks

Protective Security Policy Framework

The Australian Government protective security policy for non-corporate Commonwealth entities. Governance, information, personnel, physical — and a cyber floor that points at Essential Eight.

practitioner au-compliance IR

Ransomware payment reporting

Cyber Security Act 2024 Part 3. If you pay, or someone pays for you, the clock is 72 hours. ASD takes the form; Home Affairs watches compliance.

practitioner au-compliance frameworks

SOCI Act obligations

Security of Critical Infrastructure Act 2018, high level. Positive security obligations, cyber incident reporting, and extra duties if you are a System of National Significance.

practitioner au-compliance hardening

Third-party and supply chain

You can outsource the work. You cannot outsource the risk. Cloud shared responsibility, IRAP evidence, and ISM procurement sit on the same desk as the incident.

Definitions informed by ASD's ACSC glossary. cyber.gov.au glossary